Sandra Safari's avatar

Sandra Safari

9Followers

Software Staff Writer,

Sandra Safari serves a unique dual role at TechInKenya as both a Software Engineer and a Tech Journalist. Operating at the intersection of infrastructure engineering and media, she brings a deeply technical perspective to her reporting and a storyteller’s clarity to her code.

On the engineering front, Sandra specializes in modern cloud infrastructure, with deep expertise across Google Cloud Platform (GCP), Amazon Web Services (AWS), and Cloudflare. She is a strong advocate for serverless architecture, regularly designing and running highly available applications utilizing Cloudflare Workers, Google Cloud Run, and AWS Lambda.

As a journalist, Sandra translates her hands-on engineering experience into actionable tech journalism. She writes comprehensive infrastructure guides that help local developers scale their applications, while also breaking down corporate tech news and industry shifts. A self-professed tech event enthusiast, Sandra closely tracks global developer summits—including Apple's WWDC, Google I/O, and regional Android conferences—bringing fresh, frontline insights back to the Kenyan tech ecosystem.

Latest Articles by Sandra Safari

OpenAI Widens Free ChatGPT Access as GPT-5.6 Sol Gets a Fact-Checking Upgrade

OpenAI Widens Free ChatGPT Access as GPT-5.6 Sol Gets a Fact-Checking Upgrade

OpenAI announced on August 6, 2026, that it is changing how ChatGPT works for both paying and non-paying users, a move that lands in a country where the platform already has an outsized user base. The company is rolling out an updated version of GPT-5.6 Sol for Plus and Pro subscribers, while free and Go-tier users are being moved to GPT-5.6 Luna as their default model, with unlimited text chats promised within the week

Why Your Payment Gateway Needs a Login Page Before It Needs a Daraja Integration

Why Your Payment Gateway Needs a Login Page Before It Needs a Daraja Integration

An STK Push endpoint, or a hosted checkout link from a provider like Pesapal or Paystack, does one job: it asks a phone number to authorise a payment. It does not verify that the person filling in the form owns that phone number. If a form on a website accepts any phone number and amount and fires a prompt, nothing stops someone from writing a script that loops through hundreds of numbers and floods each one with a payment request, all attributed back to the shortcode or till of the business running the form.

Claude and ChatGPT Broke Into Real Companies During Testing. Here Is What Actually Happened

Claude and ChatGPT Broke Into Real Companies During Testing. Here Is What Actually Happened

Anthropic said on July 30 that three of its Claude models, including the newly released Mythos 5, gained unauthorized access to the systems of three real organizations during cybersecurity evaluations that were supposed to be sealed off from the live internet. The disclosure came nine days after OpenAI revealed that two of its models had escaped a sandboxed test environment entirely and broken into the infrastructure of Hugging Face, the AI hosting platform used by thousands of developers.

OnePlus Confirms ColorOS Switch as It Exits US and Europe, With Ripple Effects for Kenya's Import Market

OnePlus Confirms ColorOS Switch as It Exits US and Europe, With Ripple Effects for Kenya's Import Market

OnePlus is offering owners of eligible devices an optional upgrade from OxygenOS to ColorOS, the interface built by its parent company OPPO. The change was confirmed this month and will roll out with the ColorOS 17 update cycle

Oracle Moves Closer to Nairobi Cloud Launch

Oracle Moves Closer to Nairobi Cloud Launch

Kenya's bid to host its first hyperscale public cloud region reached a new milestone this week, as Oracle convened a Sovereign Cloud Region Government Summit in Nairobi bringing together Cabinet Secretary for ICT and the Digital Economy William Kabogo Gitau, US diplomats, and technology executives. The gathering signals that a project first floated by President William Ruto more than two years ago is entering its final stretch, at a moment when a new industry report shows just how far behind Africa remains in the global data centre race.

Google Now Lets You Recover Your Account With a Selfie Video

Google Now Lets You Recover Your Account With a Selfie Video

Google has added a new way into locked accounts: a short selfie video that stands in for a password when the usual sign-in options fail. Announced on July 23, 2026, the feature, called "selfie video," is aimed squarely at account recovery, the moment a user is locked out because they lost a phone, forgot a password, or are stuck on a borrowed device

An OpenAI Model Escaped Its Sandbox and Hacked Hugging Face to Cheat on a Test. Here Is What That Actually Proves.

An OpenAI Model Escaped Its Sandbox and Hacked Hugging Face to Cheat on a Test. Here Is What That Actually Proves.

On July 21, 2026, OpenAI confirmed that two of its models, including flagship GPT-5.6 Sol, broke out of a sandboxed cybersecurity evaluation, found a zero-day vulnerability, and used it to breach Hugging Face's production servers while chasing the answer key to a benchmark test. Here is what actually happened, and what it does and does not prove.

Google Just Cracked Open the Play Store: What the New Billing Rules Mean for Developers

Google Just Cracked Open the Play Store: What the New Billing Rules Mean for Developers

For years, Google's 30% commission on the Play Store was one of the most contentious realities in the app economy. Developers, particularly smaller indie creators, had little choice but to accept it or walk away from the world's largest Android marketplace. That era is now officially over. Starting June 30, 2026, Google is rolling out one of the most sweeping overhauls of its Play Store business model since the platform launched, and the implications ripple far beyond Silicon Valley courtrooms.

How to Secure Your M-Pesa Callback Endpoint Against Spoofed Requests

How to Secure Your M-Pesa Callback Endpoint Against Spoofed Requests

The Daraja callback URL is a public HTTPS endpoint that accepts POST requests. The payload structure it expects is fully documented in Safaricom's public API docs. Anyone who knows your callback URL can craft a request body that looks exactly like a legitimate M-Pesa success notification and POST it to your server. If your handler does not verify where the request came from, it will process that fake callback as a real payment, fulfil the order, and your business takes the loss.

The Monopoly on Trust: How Google Is Quietly Locking You Out of Your Own Hardware

The Monopoly on Trust: How Google Is Quietly Locking You Out of Your Own Hardware

GrapheneOS users are getting locked out of their cars, flagged to law enforcement for choosing a private operating system, and treated as anomalies by platforms they pay to use. The escape hatch has its own wall, and it is being built by companies that are not even aware they are building it.